SmartCard (com.apple.security.smartcard)

com.apple.security.smartcard

The payload that configures a smart card.

macOS(10.12.4)
Branch: release

Settings (6)

SettingTypeRequiredDefaultManual InstallSupported OS
UserPairing
UserPairing
If `false`, users don't get the pairing dialog, although existing pairings still work.
booleanoptionaltrue
✓Yes
macOS (10.12.4+)
allowSmartCard
allowSmartCard
If `false`, the system disables smart cards for logins, authorizations, and screen saver unlocking. It's still allowed for other functions, such as signing emails and accessing the web. The device requires a restart for a setting change to take effect.
booleanoptionaltrue
✓Yes
macOS (10.12.4+)
checkCertificateTrust
checkCertificateTrust
Configures the certificate trust check and has one of the following possible values: - `0`: Turns off certificate trust check. - `1`: Turns on certificate trust check. The device performs a standard validity check but doesn't include additional revocation checks. - `2`: Turns on certificate trust check. The device also performs a soft revocation check. Until CRL/OCSP explicitly rejects the certificate, the device considers it valid. This setting means that unavailable or unreachable CRL/OCSP allow this check to succeed. - `3`: Turns on certificate trust check. The device also performs a hard revocation check. Unless CRL/OCSP explicitly says "This certificate is OK," the device considers it invalid. This option is the most secure.
integeroptional0
✓Yes
macOS (10.12.4+)
oneCardPerUser
oneCardPerUser
If `true`, a user can pair with only one smart card, although existing pairings are allowed if already set up.
booleanoptionalfalse
✓Yes
macOS (10.12.4+)
tokenRemovalAction
tokenRemovalAction
If `1`, the device enables the screen saver when the user removes the smart card.
integeroptional0
✓Yes
macOS (10.13.4+)
enforceSmartCard
enforceSmartCard
If `true`, a user can only log in or authenticate with a smart card.
booleanoptionalfalse
✓Yes
macOS (10.13.2+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information